CVE-2026-26110Patch(microsoft / 365_apps)

MEDIUMCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • 365_copilot
  • office
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 23 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 21 signals
  • Disclosure: 5 classified signals
  • Peaked 9d ago at 5 mentions (2026-03-11); latest day: 2
  • 23 total mentions across 11 days

Affected systems

Vendors
Products
365_apps365_copilotofficeoffice_long_term_servicing_channel

5 versions affected across 4 products

Deep dive

Activity timeline23 mentions / 11d
01345Mentions · 2026-03-10: 1Mentions · 2026-03-11: 5Mentions · 2026-03-12: 4Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 2Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-20: 3Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Active Exploitation · 2026-03-11: 2Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 4Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 2Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-23: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 5Technical Details · 2026-03-12: 4Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 3Technical Details · 2026-03-21: 103-1003-1103-1203-1403-1503-1603-1803-1903-2003-2103-23
Signal classification4 categories
Patch
1565.2%
Disclosure
521.7%
Active Exploitation
28.7%
General
14.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-115
Active Exploitation2Disclosure1Patch2
2026-03-124
Patch4
2026-03-141
Patch1
2026-03-151
Patch1
2026-03-162
Disclosure1Patch1
2026-03-181
Patch1
2026-03-192
Disclosure1Patch1
2026-03-203
Disclosure1General1Patch1
2026-03-211
Patch1
2026-03-232
Patch2
Full discourse20 posts
  • SoyITPro@SoyITPro
    Patch

    🔒 Updates – Marzo 2026 Microsoft corrige 84 fallos, incluyendo 8 críticos en Windows, Office, SQL Server, .NET y Azure: 🛑 CVE-2026-26127 (.NET) – Denegación de servicio por lectura fuera de límites. 📊 CVE-2026-21262 (SQL Server) – Escalada de privilegios hasta SQLAdmin. 📄 CVE-2026-26113 (Office) – RCE por puntero no confiable (CVSS 8.4) 📄 CVE-2026-26110 (Office) – RCE por confusión de tipos, explotable vía Panel de Vista Previa. 📊 CVE-2026-26144 (Excel) – Divulgación de información sensible en generación web. 🌐 CVE-2026-23654 (GitHub/PyPI) – RCE por dependencia maliciosa en paquetes de terceros. #Security #Windows #Updates

    Post summary

    The post announces Microsoft’s March 2026 security update that patches eight critical CVEs across Windows, Office, SQL Server, .NET, Azure, and third‑party libraries, detailing the vulnerability classes and CVSS scores, but makes no reference to exploit code or ongoing attacks.

    0703131.3K
    12.3K followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    ⚠️ PATCH NOW: Microsoft just fixed 83 vulnerabilities in the March 2026 Patch Tuesday update. Some highlights security teams should pay attention to: • CVE-2026-26144 – Excel flaw that can leak sensitive data through Copilot with zero user interaction • CVE-2026-26110 / CVE-2026-26113 – Microsoft Office RCE triggered just by previewing a malicious file • CVE-2026-21262 – SQL Server privilege escalation over network The real lesson: Attackers don’t always need malware anymore. Sometimes they just need: 📄 One document 👀 One preview pane 💥 One unpatched system Patch management isn’t boring it’s your first line of defense. #CyberSecurity #PatchTuesday #ThreatInte

    Post summary

    Microsoft's March 2026 Patch Tuesday release fixes 83 vulnerabilities, including three highlighted CVEs that can be exploited via Office or SQL Server; users are urged to apply the patch immediately.

    60010120
    808 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    You don't have to open the file. You just have to look at it. Microsoft's March 2026 Patch Tuesday fixed two critical Office vulnerabilities. CVE-2026-26110 and CVE-2026-26113 where the preview pane alone is enough to trigger remote code execution. No clicks. No downloads. Just a file sitting in your inbox. The attacker's job used to be getting you to open something. Now they just need to make sure it lands.

    Post summary

    Microsoft patched CVE‑2026‑26110 and CVE‑2026‑26113, which allowed remote code execution via the Office preview pane without user interaction; no exploitation details or PoC are disclosed.

    1102082
    803 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Disclosure

    You previewed the file. Didn't open it. Didn't click anything. Just hovered over it in Outlook. That was enough. CVE-2026-26113 and CVE-2026-26110 both Critical, both in Microsoft Office, both triggered by the preview pane. Arbitrary code execution. No interaction. The attack lands the moment your eyes do. We built convenience into the kill chain.

    Post summary

    The tweet announces two new critical Microsoft Office CVEs that enable arbitrary code execution by merely previewing files in Outlook, emphasizing the risk without any user interaction.

    1101077
    803 followersView on X
  • SECUREU@secureu_in
    Patch

    And that's not all from March Patch Tuesday: - CVE-2026-26110: Office preview pane RCE, just viewing an email triggers the exploit - CVE-2026-21262: SQL Server zero-day, basic users escalate to full admin - 84 total vulnerabilities patched AI is Increasing your attack surface.

    Post summary

    March Patch Tuesday addressed 84 vulnerabilities, including an Office preview pane RCE and a SQL Server privilege‑escalation flaw that were patched during the update.

    1002074
    237 followersView on X
  • Raed alroomi@master_roomi
    General

    ثغرات MS Office وSQL Server: تظل ثغرة (CVE-2026-26110) نشطة حيث تسمح باختراق الجهاز عبر لوحة المعاينة في Outlook دون فتح الملف. كما تم رصد ثغرة (CVE-2026-21262) في SQL Server تسمح برفع الصلاحيات لدرجة مدير نظام

    Post summary

    The post reports that CVE-2026-26110 in MS Office and CVE-2026-21262 in SQL Server remain exploitable, enabling device compromise through Outlook’s preview pane and privilege escalation to sysadmin level.

    10010202
    12.8K followersView on X
  • Minery Report@MineryReport
    Patch

    Alerta Crítica: Vulnerabilidad RCE en Microsoft Office (CVE-2026-26110) 🛡️📎 Falla de seguridad de extrema gravedad descubierta en la suite Microsoft Office. El fallo permite la Ejecución Remota de Código (RCE) con una puntuación base CVSS de 8.4, afectando a millones de usuarios en Windows, Mac y Android. 🟡 ¿Cómo funciona el exploit? El peligro del "Panel de Vista Previa" La vulnerabilidad técnica se basa en una "Confusión de Tipos" (CWE-843) en la gestión de memoria del software. Lo más alarmante es la facilidad con la que puede activarse: - Sin clics: La víctima ni siquiera necesita abrir el documento malicioso. Basta con resaltar el archivo en el Explorador de Archivos de Windows para que el Panel de Vista Previa intente procesarlo, activando automáticamente el código oculto. - Baja Complejidad: El ataque no requiere privilegios elevados ni una interacción compleja por parte del usuario. 🟡 Vector Local, Atacante Remoto: Aunque se clasifica como RCE, el código se ejecuta localmente en la máquina tras ser descargado (vía email o web), otorgando al atacante control sobre el sistema de la víctima. Software Afectado (Alcance Masivo): - Microsoft Office 2016 y 2019 (32 y 64 bits). - Microsoft 365 Apps para Empresas. - Microsoft Office LTSC 2021 y 2024 (Windows y Mac). - Microsoft Office para Android. ⚠️ Estado Actual y Recomendaciones Afortunadamente, por ahora no hay evidencia de explotación activa en el mundo real, lo que da una ventana de oportunidad para protegerse: - Actualizar de Inmediato: Instalar los parches de seguridad del Patch Tuesday de marzo de 2026 lanzados por Microsoft. - Actualizar Android: Asegurarse de que la app de Office en dispositivos móviles se actualice desde Google Play Store. - Medida de Mitigación (Urgente): Si no puedes parchear hoy mismo, desactiva el Panel de Vista Previa en el Explorador de Archivos de Windows. Esto elimina el vector de ataque más directo. ⚠️ Resumen Estratégico para la Dirección: En marzo de 2026, la confianza en las herramientas de productividad sigue siendo un vector de entrada preferido. Una vulnerabilidad que se activa con solo "mirar" un archivo en la vista previa rompe la regla clásica de "no abrir archivos sospechosos". La prioridad absoluta esta semana es la actualización de todas las instancias de Office en la empresa, empezando por los equipos que manejan información sensible. #MicrosoftOffice #CVE202626110 #RCE #Ciberseguridad2026 #InfoSec #ElHackerNET #PatchTuesday #VistaPrevia #WindowsSecurity

    Post summary

    The post outlines a high‑severity RCE vulnerability in Microsoft Office that activates via the Preview pane, and urges immediate patching or disabling of that feature to mitigate the risk.

    0101056
    300 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Patch

    🎙️ RadioCSIRT Ép.595 – Épisode Spécial du jeudi 12 mars 2026 Un seul sujet. Un cycle qui marque l'histoire des CVE : le Patch Tuesday Microsoft de mars 2026. 🔴 Microsoft Patch Tuesday – 79 vulnérabilités corrigées, deux zero-days publiquement divulgués. CVE-2026-26113 et CVE-2026-26110 : deux RCE critiques dans Microsoft Office déclenchables par simple visualisation d'un message dans le volet de prévisualisation, sans interaction utilisateur. 🔴 CVE-2026-26144 – Microsoft Excel et Copilot Agent Mode. Divulgation d'informations critique : un attaquant peut forcer Copilot à exfiltrer des données via un trafic réseau non prévu. Attaque zero-click documentée. 🔴 CVE-2026-21262 – SQL Server, élévation de privilèges jusqu'au niveau sysadmin via le réseau (CVSS 8.8). Zero-day publiquement divulgué avant correctif. CVE-2026-26127 – .NET, déni de service réseau sans authentification. 🔴 Six vulnérabilités Important signalées comme prioritaires par Cisco Talos et Tenable : Windows Graphics Component, Windows Kernel, Windows Accessibility Infrastructure, Windows SMB Server, Ancillary Function Driver for WinSock, Winlogon (découverte par Google Project Zero). 🔴 CVE-2026-21536 – CVSS 9.8 Critical. Première CVE officiellement attribuée à un agent IA autonome : XBOW, agent de penetration testing entièrement automatisé, sans accès au code source. Microsoft a corrigé côté serveur, sans action requise des utilisateurs. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-595-episode-special-patch-tuesday-microsoft-mars-2026/ 📖 Analyse complète sur le blog : https://blog.marcfredericgomez.fr/microsoft-patch-tuesday-mars-2026-79-vulnerabilites-corrigees-deux-zero-days-divulgues/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #PatchTuesday #Microsoft #CVE #ZeroDay #RCE #Windows #Office #SQLServer #Copilot #AI #XBOW #PatchManagement #VulnerabilityManagement #InfoSec #CERT #CSIRT #SOC #CISO #VOC #Patch

    Post summary

    The post details Microsoft Patch Tuesday 2026, noting 79 remediation items including two Office RCEs, a SQL Server admin‑level privilege escalation, and an AI‑controlled zero‑click exploit, while highlighting that patches were applied server‑side without user action.

    0002060
    413 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft Office の RCE 脆弱性 CVE-2026-26110 が FIX:タイプ・コンフュージョンに起因 https://iototsecnews.jp/2026/03/11/critical-vulnerability-in-microsoft-office-allows-malicious-code-to-run-remotely/ この脆弱性 CVE-2026-26110 は、プログラムがデータ・タイプを正しく判別しない、タイプ・コンフュージョンという現象に起因します。 本来は A というルールで扱うべきデータを、誤って B というルールで処理してしまうことで、予期せずにメモリの中身が書き換わってしまいます。 プログラムが想定外のデータ・タイプでリソースにアクセスする際の挙動が、セキュリティ上の大きな欠陥となります。 この CVE-2026-26110 (タイプ・コンフュージョン) を悪用されると、特別な権限がなくても外部からリモート・コード実行 (RCE) が引き起こされる恐れがあるため、迅速なパッチ適用がとても大切です。 ご利用のチームは、ご注意ください。 #CVE202626110 #Microsoft #Office #Vulnerability

    Post summary

    The post announces a type‑confusion vulnerability (CVE‑2026‑26110) in Microsoft Office that can lead to remote code execution and stresses the need for prompt patching.

    01000128
    484 followersView on X
  • kotaro@サイバーセキュリティ情報発信@ngsk_ciso
    Patch

    「クリックしてないのに…」が現実になってきた話。 Outlookのプレビューペインを眺めているだけで、PCが侵害される可能性のある脆弱性が2件(CVE-2026-26110/26113)、3月の月例パッチで修正されました。 メールを開いてもいない、添付ファイルを触ってもいない。それでも危ないかもしれない、という状況ですね。 まず確認したいのは、3月のWindows Updateが適用済みかどうか。 「設定 → Windows Update → 更新プログラムの確認」で済む話なので、朝イチでさっと見てみると安心かも。 今すぐパッチが当てられない端末があるなら、暫定策として「プレビューペインを無効化」も有効です。 Outlook → 表示タブ → 閲覧ウィンドウ → オフ これだけで攻撃経路を一つ塞げます。 Microsoft 365もオンプレのOutlookも対象になりますので、職場で使っている方は一度確認してみてください。 #情シス #セキュリティ #フィッシング 出典: https://www.helpnetsecurity.com/2026/03/11/march-2026-patch-tuesday/

    Post summary

    The post informs users that CVE‑2026‑26110 and CVE‑2026‑26113, affecting Outlook preview pane, are fixed by the March 2026 Windows Update and suggests disabling the preview pane as a temporary measure. No PoC or active exploitation details are provided.

    0000039
    22 followersView on X
  • History Hype@HistoryHype_
    Patch

    Friðrik Skúlason’s 1995 Concept macro virus taught us local Office files could kill. Fast-forward to CVE-2026-26110 hiding in the Preview Pane—some lessons never age. Patch now https://www.windowscentral.com/software-apps/the-office-local-loophole-why-microsofts-latest-critical-patches-arent-just-for-it-pros https://t.co/DS5zg038s8

    Post summary

    The post announces CVE-2026-26110 and urges users to apply the latest critical patch, with a link to the patch details.

    0000032
    3 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    CVE-2026-26113 and CVE-2026-26110. Both critical. Both Office. Both sitting in the preview pane your IT team never disabled because "nobody complained." Disable the preview pane in Outlook now — File → Options → Mail → Reading Pane. Takes 11 seconds. (Microsoft MSRC March 2026) When did your org last patch Office? Drop the month below genuinely curious how exposed this thread is.

    Post summary

    The post highlights two critical Office CVEs and provides a clear workaround—disabling the Outlook preview pane—and prompts users to confirm their last patch date.

    0000062
    800 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26110 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. https://www.cve.org/CVERecord?id=CVE-2026-26110

    Post summary

    The entry announces CVE-2026-26110, a type confusion vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally.

    00000195
    56.7K followersView on X
  • CybrPulse@CybrPulse
    Patch

    March Patch Tuesday: 77 CVEs, no zero-days. Two Office flaws to prioritize: CVE-2026-26113 and CVE-2026-26110 both trigger RCE just by previewing a message. No clicks needed. Also CVE-2026-24294 (SMB auth bypass). Patch now. https://krebsonsecurity.com/2026/03/microsoft-patch-tuesday-march-2026-edition/ #infosec

    Post summary

    The post announces Microsoft March Patch Tuesday, names CVEs causing RCEs and an SMB auth bypass, and urges users to apply patches, but provides no proof‑of‑concept, exploit code, or evidence of current exploitation.

    0000053
    19 followersView on X
  • Grok@grok
    Patch

    네, 대부분 사실이에요. 3월 Microsoft 패치에서 Office 미리보기 창만으로도 악성코드 실행 가능한 RCE 취약점(CVE-2026-26110, 26113 등)이 실제로 패치됐습니다. 네트워크 관련 고위험 RCE도 여러 개 있어요. CISA가 '긴급 명령' 내린 건 확인 안 됐고, 아직 KEV에도 안 올라왔지만 업데이트는 지금 바로 하세요. 안전이 최우선!

    Post summary

    Microsoft released a March patch fixing CVE-2026-26110/26113, which allow remote code execution via the Office preview pane, and users are urged to update immediately.

    0000083
    8.5M followersView on X
  • Grok@grok
    Patch

    @JeongMi86989473 @virtual_lab101 네, 3월 마이크로소프트 패치에서 Office 미리보기 창만으로도 코드 실행 가능한 치명적 RCE 취약점(CVE-2026-26110, 26113)이 수정됐어요. 바로 업데이트 강력 추천! CISA '긴급 명령'은 확인 안 됐지만, 보안 패치 적용이 최선입니다. (공식 MS 업데이트 가이드 참고)

    Post summary

    Microsoft’s March patch addressed critical RCE vulnerabilities (CVE-2026-26110/26113) in Office preview; users are urged to update to mitigate the risk.

    000001.2K
    8.4M followersView on X
  • Giulio Sistilli@GiulioSistilli
    Patch

    New CVEs alert: Microsoft just patched 83+ flaws, including 8 Critical ones: • CVE-2026-26110 & CVE-2026-26113: Office RCE via preview pane (CVSS 8.4) • CVE-2026-21262: SQL Server priv esc (publicly disclosed zero-day) • CVE-2026-26127: .NET DoS (another public zero-day) #CVE

    Post summary

    Microsoft released patches for over 80 CVEs, including 8 critical flaws that expose Office RCE via preview pane, SQL Server privilege escalation, and a .NET denial‑of‑service vulnerability.

    0000094
    27 followersView on X
  • ✮ Cymon Skinner ✮@CymonSkinner
    Patch

    CVE-2026-26110, a type confusion vulnerability in Microsoft Office, enables unauthorised attackers to execute malicious code locally via the Preview Pane. This flaw affects Office 2016 through 2024 and Microsoft 365 across Windows and macOS, with low attack complexity and no privileges required. CISOs should prioritise March 2026 Patch Tuesday updates to mitigate risks of system compromise and data exfiltration, especially in shared file environments. Proactive patch management remains a cornerstone of robust SOC operations.

    Post summary

    The post highlights CVE‑2026‑26110, a type‑confusion flaw in Microsoft Office, and urges CISOs to apply the March 2026 Patch Tuesday update to mitigate the risk of local code execution.

    0000067
    711 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploiting Microsoft Office vulnerabilities (CVE-2026-26110, CVE-2026-26113) demonstrate a classic privilege escalation to lateral movement pattern. Once elevated access is achieved, compromised credentials enable network-wide pivoting. Runtime segmentation helps contain such post-compromise activity. #ZeroDay 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/microsoft-march-2026-patch-tuesday-addresses-83-vulnerabilities-including-two-publicly-disclosed-zero-days

    Post summary

    The post reports that attackers are actively exploiting two Microsoft Office CVEs to achieve privilege escalation and lateral movement, with runtime segmentation used to contain post‑compromise activity.

    0000052
    1.9K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔒 Urgent patch: two Office flaws let attackers run code remotely—install the March 2026 updates now before the chaos starts. #WindowsForum #PatchTuesday #CVE26110 #CVE26113 https://windowsforum.com/threads/urgent-office-patch-fix-cve-2026-26110-and-cve-2026-26113-now.404710/?utm_source=rss&utm_medium=rss

    Post summary

    The post warns users to apply the March 2026 Office update immediately to mitigate two remote code execution flaws (CVE-2026-26110 and CVE-2026-26113).

    0000041
    1.0K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoft365_copilot-android-
Appmicrosoftoffice2016-x64
Appmicrosoftoffice2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-

Explore more